7.8

CVSS3.1

CVE-2025-38233 - powerpc64/ftrace: fix clobbered r15 during livepatching

In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatching While r15 is clobbered always with PPC_FTRACE_OUT_OF_LINE, it is not restored in livepatch sequence leading to not so obvious fails like below: BUG: Unable to handle kern…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 4:16 p.m.

5.5

CVSS3.1

CVE-2025-38177 - sch_hfsc: make hfsc_qlen_notify() idempotent

In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: make hfsc_qlen_notify() idempotent hfsc_qlen_notify() is not idempotent either and not friendly to its callers, like fq_codel_dequeue(). Let's make it idempotent to ease qdisc_tree_reduce_backlog() callers' life: 1. up…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

5.5

CVSS3.1

CVE-2025-38184 - tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer

In the Linux kernel, the following vulnerability has been resolved: tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer The reproduction steps: 1. create a tun interface 2. enable l2 bearer 3. TIPC_NL_UDP_GET_REMOTEIP with media name set to tun tipc: Started in network mode tipc…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:53 p.m.

7.8

CVSS3.1

CVE-2025-38187 - drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is released after being passed to r535_gsp_rpc_send(). When sending the initial fragment of a large RPC and passing the caller's RPC container, the conta…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 8:50 p.m.

5.5

CVSS3.1

CVE-2025-38191 - ksmbd: fix null pointer dereference in destroy_previous_session

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->user is not set yet, It can pass the user …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:24 p.m.

7.8

CVSS3.1

CVE-2025-38201 - netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof() when resizing hashtable because __GFP_NOWARN is unset. Similar to: b541ba7d1f5a ("n…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 1:27 p.m.

7.8

CVSS3.1

CVE-2025-38180 - net: atm: fix /proc/net/atm/lec handling

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety against dev_lec[] changes. It appears it had dev_put() calls without prior dev_hold(), leading to imbalance and UAF.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:36 p.m.

5.5

CVSS3.1

CVE-2025-38220 - ext4: only dirty folios when data journaling regular files

In the Linux kernel, the following vulnerability has been resolved: ext4: only dirty folios when data journaling regular files fstest generic/388 occasionally reproduces a crash that looks as follows: BUG: kernel NULL pointer dereference, address: 0000000000000000 ... Call Trace: <TASK> ext4_b…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 3:17 p.m.

7.8

CVSS3.1

CVE-2025-49809 - mtr: From CVEorg collector

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-38216 - iommu/vt-d: Restore context entry setup order for aliased devices

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Restore context entry setup order for aliased devices Commit 2031c469f816 ("iommu/vt-d: Add support for static identity domain") changed the context entry setup during domain attachment from a set-and-check policy to …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 3:45 p.m.
Total resulsts: 346616
Page 4537 of 34,662
Β« previous page Β» next page
Filters